symphony+x+underworld++album_10924_i35562265_il345.exe.zip

The file symphony+x+underworld++album_10924_i35562265_il345.exe.zip has been detected as a potentially unwanted program by 23 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from downprov.red-6-small-button.com and multiple other hosts.
MD5:
7d10ca03dfb0c22024c6dccf176dd7bb

SHA-1:
f682714b74fe0b520cbb4f78a704f42817c3c393

SHA-256:
8829a0bcc6540530bee2dfd96bb840b993b5c33528ee1620a882ca820272b2f5

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 1:23:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Jatif.320
5881082

Avira AntiVirus
ADWARE/Amonetize.Gen7
8.3.1.6

Arcabit
Trojan.Application.Jatif.320
1.0.0.425

avast!
Win32:Amonetize-JO [PUP]
2014.9-150803

AVG
Generic
2016.0.3029

Bitdefender
Gen:Variant.Application.Jatif.320
1.0.20.1075

Comodo Security
Application.Win32.LoadMoney.IARS
22920

Dr.Web
infected with Trojan.Amonetize
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Jatif.320
10.0.0.5366

ESET NOD32
Win32/Amonetize.DW potentially unwanted application
7.0.302.0

F-Prot
W32/S-53544127
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Jatif
11.2015-03-08_2

G Data
Gen:Variant.Application.Jatif.320
15.8.25

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

MicroWorld eScan
Gen:Variant.Application.Jatif.320
16.0.0.645

Norman
Gen:Variant.Application.Jatif.320
07.07.2015 03:10:29

Panda Antivirus
Trj/Genetic.gen
15.08.03.06

Quick Heal
PUA.Bershnetll.Gen
8.15.14.00

Sophos
Amonetize
4.98

Trend Micro House Call
TROJ_GE.A8B4863C
7.2.215

Trend Micro
TROJ_GE.A8B4863C
10.465.03

Vba32 AntiVirus
Signed-Downware.Dlhelper
3.12.26.4

VIPRE Antivirus
Amonetize
42570

File size:
1.4 MB (1,517,516 bytes)

Common path:
C:\users\{user}\downloads\symphony+x+underworld++album_10924_i35562265_il345.exe.zip

The file symphony+x+underworld++album_10924_i35562265_il345.exe.zip has been seen being distributed by the following 2 URLs.